
Blog Post
What the Cyber Risk Register Does Between Reviews
September 21, 2026
Registers go stale between reviews and the standard advice is to review more often. Quarterly at minimum, event-triggered updates, telemetry feeding the entries automatically. All of it sound and all of it treating decay as one problem.
It is three problems that decay at different rates and need different remedies, and the most useful thing a register produces between reviews is not a current entry at all.
Which Three Things Drift?
Inventory, scoring and ownership, and conflating them is why the remedy usually addresses the cheapest one.
Inventory drift means entries describe systems that no longer exist and omit systems that do. New deployments, retirements and reconfigurations all move it, and the register only learns about them when somebody tells it.
Scoring drift means an entry's likelihood or impact has changed while the entry has not. A control improved, an asset value grew, a dependency was added. Nothing about the entry looks wrong, which is what makes this the hardest of the three to notice.
Ownership Drift Is the Easiest to Fix
People leave and change roles, so entries carry owners who no longer hold the role or no longer work there. Directory data detects that automatically and almost nobody wires it up, which makes it the cheapest correction available and the one most often left to a manual review.
What Does the Register Do Between Reviews?
It asserts things that can be tested, which is a more useful description than saying it decays.

An entry saying a scenario affects forty systems is a claim. Discovery reporting forty-seven is another claim. The difference between them is information neither produces alone, and it is available continuously without anybody reviewing anything.
Which Makes the Delta the Output
The valuable between-review artifact is the divergence rather than the register. A register that is wrong in a measurable way is more useful than one nobody has checked, because the measurement tells you where to look and how much the position has moved since anyone last agreed it.
Where Should a Review Start?
From the divergence rather than from entry one, which inverts how most reviews are run.
Walking a register in order spends the most time on the entries that have not changed, because they are at the top and they are easy. Starting from what diverged puts the effort on the entries where reality and the record disagree, and finishes the rest quickly because nothing moved.
What Does That Change About Duration?
It shortens the review and improves it at the same time, which is rare. A quarterly review of eighty entries where six diverged is a short meeting about six things rather than a long meeting about eighty, and the six are where the decisions are, which a register built to be operated sets out.
How Fast Is Your Register Decaying?
Measurable from data you already hold, and almost nobody computes it.

Count the proportion of entries that changed at the last review. A large share means the interval is too long for the rate at which the environment moves. A very small share means either the interval is about right or the review is not looking hard, and distinguishing those two requires checking the divergence independently.
Which Sets the Interval From Evidence
Most review cadences are inherited rather than chosen. A register where a third of entries move each quarter is telling you the cadence should be monthly for the volatile subset, and one where almost nothing moves is telling you the effort belongs elsewhere. The figure decides it rather than a convention.
What Can a Register Never Tell You?
Anything about a risk nobody entered, which is a different failure from decay and is unaffected by review frequency.
Every problem discussed so far concerns entries becoming wrong. The larger problem is categories that were never added, since a register is a record of what somebody thought to write down. Reviewing it more often examines the same list more carefully and cannot surface what is absent from it.
What Addresses the Absence?
Something outside the register, which is why discovery and the register are different instruments rather than versions of the same one. Observed activity naming systems, data flows and dependencies nobody recorded is the input that grows the list, and real-world events entering the register is the other direction of the same idea.
What Does an Examiner Assess?
The process rather than the entries, which changes what the register should record about itself.
A register with a review date shows that a review happened. A register showing what changed between reviews, why, and who decided shows a process operating. An examiner asking how the organization keeps its risk picture current is assessing the second, and a dated snapshot answers the question somebody else asked.
Which Field Is Usually Missing?
The reason an entry changed. Registers commonly record current values and a modification date, so a score that moved from high to medium shows the new value with no record of what justified it. The reason is the field an examiner asks about and the one nobody captures, and records that survive an audit turns on exactly that.
Should Every Entry Be on the Same Cadence?
No, and treating the register as one artifact with one review cycle is what produces the stale impression in the first place.
Entries differ enormously in volatility. A scenario resting on a stable asset base and a mature control moves rarely, so reviewing it quarterly examines something that has not changed since the last three reviews. A scenario resting on a growing cloud footprint or a newly deployed capability moves constantly, and a quarterly cycle means it is wrong for most of the quarter.
How Would You Sort Them?
Sort by what the entry depends on rather than by its score. An entry whose inputs are asset values that change annually inherits that cadence. One whose inputs include a system count that changes weekly inherits that instead. The dependency sets the review interval, and it is knowable from the entry itself.
Does That Complicate the Process?
It simplifies it, since most registers have a small volatile subset and a large stable majority. Reviewing the volatile subset monthly and the rest annually is less total effort than reviewing everything quarterly, and the volatile entries spend far less time wrong, which the way an exposure figure moves in steps explains.
What Can Be Set Up This Month?
Three things, in ascending order of effort, and the first takes an afternoon.
Wire owner validation to the directory, so entries with departed or moved owners flag themselves rather than waiting for a review. Compute the divergence between the register's system count and whatever discovery reports, since that single number tells you how far the inventory has drifted. Then record a reason against every future change, because it cannot be reconstructed later and it is the field that turns a list into evidence. Cyber risk quantification attached to entries makes the scoring drift measurable as well, which is otherwise the hardest of the three to see.
The Delta Is the Deliverable
Register decay is three separate problems. Inventory drift needs discovery, scoring drift needs re-derivation, and ownership drift is detectable from the directory and almost never wired up. Between reviews the register asserts things that can be tested, so the useful output is the divergence between what it claims and what is observed rather than a current entry. Starting a review from that divergence rather than from entry one shortens the review and improves it. The proportion of entries that changed last time sets the cadence from evidence rather than convention. No review frequency addresses a risk nobody entered either, which is why discovery and the register are different instruments. Kovrr's cyber risk quantification keeps a dated figure against each entry, which is what makes drift visible rather than assumed.
To see register entries carrying dated figures that can be tested against the current position, book a demo with our risk experts.
Register Drift FAQs
Speak to an ExpertWhich three things drift in a risk register?
Inventory, scoring and ownership. Inventory drift means entries describe systems that no longer exist and omit systems that do, moved by new deployments, retirements and reconfigurations. Scoring drift means an entry's likelihood or impact has changed while the entry has not, because a control improved or an asset value grew, which makes it the hardest to notice. Ownership drift means entries carry owners who have left or changed role.
Which drift is easiest to fix?
Ownership. People leave and change roles, so entries carry owners who no longer hold the role, and that is detectable from the directory automatically. Almost nobody wires it up, which makes it the cheapest correction available and the one most often left to a manual review. Inventory drift needs discovery and scoring drift needs re-derivation, so both cost considerably more.
What does a register do between reviews?
It asserts things that can be tested. An entry saying a scenario affects forty systems is a claim, and discovery reporting forty-seven is another claim, so the difference between them is information neither produces alone and it is available continuously without anybody reviewing anything. A register that is wrong in a measurable way is more useful than one nobody has checked.
Where should a review start?
From the divergence rather than from entry one. Walking a register in order spends the most time on entries that have not changed, because they are at the top and easy. Starting from what diverged puts effort where reality and the record disagree, and finishes the rest quickly. A quarterly review of eighty entries where six diverged becomes a short meeting about six things.
How do you measure the decay rate?
Count the proportion of entries that changed at the last review. A large share means the interval is too long for the rate at which the environment moves. A very small share means either the interval is about right or the review is not looking hard, and distinguishing those requires checking the divergence independently. That figure sets the cadence from evidence rather than convention.
What can a register never tell you?
Anything about a risk nobody entered, which is a different failure from decay and unaffected by review frequency. Every decay problem concerns entries becoming wrong, while the larger problem is categories never added, since a register records what somebody thought to write down. Reviewing more often examines the same list more carefully and cannot surface what is absent from it, which requires observed activity from outside the register.




